• Silicon Labs
  • 資料
  • コミュニティ
Silicon Labs
  • ⟵ 戻る
    製品
    2026 Tech Talks
    より深い学習、より大きな発想、そして次のブレークスルーを市場に迅速に届けるための専門家の指導に備えましょう。
    ワイヤレスワイヤレス
    Amazon Sidewalk
    Bluetooth
    LPWAN
    Matter
    マルチプロトコル
    独自規格
    Thread
    Wi-Fi
    Wi-SUN
    Z-Wave
    Zigbee
    組み込みハードウェア組み込みハードウェア
    ボードとキット
    MCU
    電源管理
    センサー
    USB ブリッジ
    ワイヤレス・モジュール
    ワイヤレス SoC
    IoTテクノロジーIoTテクノロジー
    チャネルサウンディング
    エナジー・ハーベスティング(環境発電)
    機械学習
    セキュリティ
    サービスサービス
    カスタム部品製造
    開発者サービス
    SDK 拡張メンテナンスサービス
  • ⟵ 戻る
    アプリケーション
    スマートホームスマートホーム
    家電
    屋外向け接続
    エンターテイメントデバイス
    IoT ゲートウェイ
    LED 照明
    Residential Smart Energy
    セキュリティカメラ
    センサー
    スマートロック
    スイッチ
    産業用 IoT 産業用 IoT
    アクセス制御
    資産トラッキング
    電池駆動式ツール
    サーキット・ブレーカー
    商業用照明
    電気サブメーターリング
    非常用照明
    工場自動化
    ヒューマン・マシン・インターフェース
    Industrial Smart Energy
    工業用ウェアラブル
    予知保全
    プロセスオートメーション
    スマート HVAC
    スマートシティスマートシティ
    バッテリー貯蔵
    EV 充電ステーション
    スマート農業
    スマート・ビル
    スマート・メータリング
    スマート・ソーラー PV システム
    街灯
    スマートリテールスマートリテール
    商業用照明
    方向検知
    電子棚札
    損失防止
    Wi-Fi アクセス・ポイント
    コネクテッドヘルスコネクテッドヘルス
    ポータブル医療機器
    スマート病院
    スマート・ウェアラブル・デバイス
  • ⟵ 戻る
    ソフトウェアとツール
    Simplicity Studio 6
    IoT 開発への近道
    ソフトウェア&ツール ソフトウェア&ツール
    Simplicity AI SDK
    ソフトウェア 開発キット (SDK)
    SDK リリースノート
    ソフトウェア・リファレンス・ドキュメント
    ソフトウェア開発ツール
    ハードウエア開発キット
    ハードウエア資料
    GitHub のリソース
    開発者のジャーニー 開発者のジャーニー
    AI/ML
    Amazon Sidewalk
    Bluetooth
    Bluetooth メッシュ
    Google Home
    Matter
    Zephyr向けSimplicity SDK
    Wi-Fi
    サービスサービス
    カスタム部品製造
    開発者サービス
    SDK 拡張メンテナンスサービス
  • ⟵ 戻る
    リソース
    文書文書
    ブログ
    ケース・スタディ
    ソフトウェアの資料
    テクニカルライブラリ
    ホワイトペーパー
    トレーニングトレーニング
    Tech Talks 2026
    Works With オンデマンド 2025
    ウェビナー
    カリキュラム
    パートナーパートナー
    チャネルと流通
    エコシステム・パートナー
    パートナー・ネットワーク
    サービスサービス
    カスタム部品製造
    開発者サービス
    SDK 拡張メンテナンスサービス
    サポートサポート
    コミュニティ
    チケットの送信
    品質と梱包
    ご購入方法
    Vulnerability and Bug Bounty
    お問い合わせ
  • ⟵ 戻る
    会社
    当社について 当社について
    コミュニティに対するコミットメント
    Silicon Labs でのインクルージョン
    経営陣
    セキュリティ
    持続可能性持続可能性
    環境、社会、ガバナンス
    品質
    サプライチェーンの責任
    ニュース & イベント ニュース & イベント
    ブログ
    ニュースルーム
    イベント
    投資家向け広報投資家向け広報
    年次報告書および代理人
    取締役会
    コーポレートガバナンス
    四半期決算
    SEC 申請
    キャリアキャリア
    ハイデラバード拠点
    その他のグローバルオフィス
    お問い合わせ
日本語
  • English
  • 英語
  • 简体中文
  • 日本語
AIに質問する
AskAI
AIに質問する
//
セキュリティ // セキュリティ脆弱性に関するよくある質問

セキュリティ脆弱性に関するよくある質問

Silicon Labs では、セキュリティ研究コミュニティ、顧客、パートナーと協力して、責任を持ってタイムリーに脆弱性を特定し、対処することに尽力しています。CVE 番号付け機関(CNA)として、Silicon Labs は脆弱性の開示と管理に関する業界慣行に従い、プロセス全体を通して透明性と説明責任を確保します。

このFAQページは、潜在的なセキュリティ問題の報告方法、開示プロセス中に予想されること、および脆弱性開示の処理方法について明確なガイダンスを提供することを目的としています。研究者、開発者、顧客のいずれであっても、安全なエコシステムの維持にご協力いただきありがとうございます。

脆弱性を報告する

To report a product security vulnerability, please register and create an account at community.silabs.com and click on the "Vulnerability Disclosure" tab on the top right hand corner to select the "Vulnerability Report Submission" option in the drop down menu.

企業資産のセキュリティ脆弱性を報告するには、 community.silabs.com で登録してアカウントを作成し、右上の「Vulnerability Disclosure」タブをクリックして、ドロップダウンメニューから「Vulnerability Report Submission」を選択してください。

以下を提供してください。 

  • 脆弱性の明確な説明
  • 影響を受けた製品とバージョン
  • 問題を再現するためのステップ。
  • 潜在的な影響(データ侵害、システム侵害など)。
  • 概念実証コードまたはスクリーンショット(該当する場合)
  • フォローアップのための連絡先情報
  • 帰属情報(帰属を希望する場合
  • For coding vulnerabilities, please point to the exact location of the vulnerable files.

これにより、当社のPSIRTは問題を迅速に評価し、対処することができます。

Since registration involves an email address, and requires communication to address an issue, anonymity is likely going to be based on the information you provide at registration. In addition, the eligibility for our Bug Bounty Program will require some level of self-identification to be provided with directions on rewards. 



開示プロセス

The vulnerability is assessed based on several factors, which determine its priority.  The approach to resolving the issue then follow and an advisory or disclosure is made for the vulnerability and fix, if applicable. 

開示: 当社は、登録ユーザーに脆弱性を通知するセキュリティアドバイザリを発行します。セキュリティアドバイザリ通知のサインアップ方法については、ここをクリックしてください。

はい。当社は、連携した脆弱性開示の原則に従います。当社では、報告者と協力して、公開前に脆弱性を検証して修正を行い、顧客へのリスクを最小限に抑えます。当社では、利用可能な修正とともにセキュリティアドバイザリを公開することを目指しています。場合によっては、修正がリリースされないことがあります。

Researchers are welcome to reference the public security advisory and published CVEs in their communications or publications.

You can view previously published security advisories in our GitHub page.

You can sign up for email notifications when a new Security Advisory is published by Watching the security advisory GitHub repo. Note that a GitHub account is needed to watch GitHub repos. You will receive notifications whenever a new advisory is published. The filterable dashboard linked in the repo description can be used to determine if any of the advisories are relevant to your product(s).



Bug Bounty Questions

はい。Bug Bounty Programは、脆弱性の深刻度と影響に基づいて、対象となる提出に報酬を払います。See our Vulnerability Disclosure Program (VDP) FAQ for eligibility, scope, and reward details. 

Qualifying vulnerabilities include those affecting our semiconductor products, firmware, or related software. 当社が報酬を支払った一般的な脆弱性には、いかに関連するものがあります。

  • メモリ破損
  • 暗号上の欠陥
  • バッファ・オーバーフロー

Vulnerabilities discovered in our enterprise assets do not qualify for the bug bounty and are only part of the Vulnerability Disclosure Program. See our security vulnerability disclosure policy for more details.

Once you register as a researcher at community.silabs.com, and meet the requirements listed in the security vulnerability disclosure policy, you should be able to participate in the bug bounty program. 

We only pay for confirmed vulnerabilities, that had not already been reported. Payments depend on the priority that Silicon Labs assigns to the vulnerability after internal review.  The pricing of the bounty by priority is available in the Vulnerability Disclosure Program (VDP) FAQ.



企業関連の質問

To report an enterprise asset security vulnerability, please register as a researcher at community.silabs.com and from there you will be able to submit vulnerability reports.



一般的な質問

当社の製品セキュリティインシデント対応チーム(PSIRT)は、当社製品のセキュリティ脆弱性の特定、評価、および解決を管理します。当社は、適時の修正と透明性のあるコミュニケーションを確保するために、研究者、顧客、パートナーと連携します。

当社は、業界標準と内部評価を組み合わせて修正の優先付けを行います。We utilize the Common Vulnerability Scoring System (CVSS) 4.0, as well as other internal criteria, which enables us to assess the severity of each issue. 重大な脆弱性は最優先され、90日以内に開示して解決することを目指しています。

はい、当社はCNA(CVE Numbering Authority)です。これにより、適切な場合には確認された脆弱性にCVEを割り当てることができ、セキュリティ問題の公開を円滑に行えます。当社は、各セキュリティアドバイザリに関連するCVE番号を記載します。

当社は、データのプライバシーを真剣に受け止めています。報告は機密扱いされ、安全に保管され、解決に関与するチームメンバーのみと共有されます。

Silicon Labs

当社とつながる

製品リリースとリソース、資料の更新、PCN 通知、今後のイベントなどなど、Silicon Labs の最新製品の情報をお届けします。

  • 会社概要
  • 採用情報
  • コミュニティ
  • お問い合わせ
  • 企業責任
  • IR/投資家情報
  • プレスルーム
  • プライバシーおよび利用規約
  • サイトへのフィードバック

ご連絡ください:

Silicon Labs の BiliBili アイコン
Copyright Silicon Laboratories. All rights reserved.

ファイルのダウンロードはすぐに始まります

をダウンロードしていただき、ありがとうございます。

ダウンロードに問題がある場合は、セールス・サポートまたは製品テクニカル・サポートへお問い合わせください。

閉じる
ロードの結果
閉じる

少なくとも1つの列を選択してください。

Powered by Translations.com GlobalLink OneLink Software